How to report security vulnerabilities

Important: Please don’t open a public GitHub issue for security problems.

To report a security issue, file a Private Security Report with a description of the issue, the steps you took to create the issue, affected charm and version, and, if known, mitigations for the issue.

The repository admins will be notified of the issue and will work with you to determine whether the issue qualifies as a security issue and, if so, in which component. We will then handle figuring out a fix, getting a CVE assigned and coordinating the release of the fix.

The Ubuntu Security disclosure and embargo policy contains more information about what you can expect when you contact us and what we expect from you.

This page was last modified a day ago. Help improve this document in the forum.